Skip to content
CAI
Software that uses CAICheck a score

sentemon/MessagingPlatform

39.2

Weak · 21 September 2026

2.6k

lines of production code

C#

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a real-time messaging platform that enables users to create and manage private, group, and channel-based chats with full CRUD operations on messages and participants. The system enforces strict role-based access control and ownership rules for chat and message management, utilizing a CQRS architecture with SignalR for live updates. It supports user authentication, profile management, and chat participant administration through a .NET backend and Angular frontend.

Features

Add CQRS queries for retrieving users by ID, username, and all users

The application layer now includes new CQRS query handlers for fetching user data: GetAllUsersQuery retrieves all users, GetUserByIdQuery fetches a user by their unique identifier, and GetUserByUsernameQuery retrieves a user by their username. Each query is paired with a corresponding handler that delegates to the IUserRepository, enabling the backend to serve these specific user lookup operations.

backend/src/MessagingPlatform.Application/CQRS/Users/Queries · high confidence

Add authenticated chat messaging via SignalR hub

The backend now exposes a new ChatHub that allows authenticated users to send chat messages in real-time. The hub validates the user's identity via a 'Sid' claim, processes the message through the existing AddMessageCommandHandler, and broadcasts the new message to all connected clients in the chat, ensuring local state synchronization.

backend/src/MessagingPlatform.Api/Hubs · high confidence

Add chat retrieval with membership validation

Users can now retrieve a specific chat by its ID, but the system enforces that the requesting user must be a member of that chat. If the chat does not exist or the user is not a participant, the operation fails with an appropriate error, preventing unauthorized access to chat data.

backend/src/MessagingPlatform.Application/CQRS/Chats/Queries/GetChatById · high confidence

Added CQRS handlers for chat participant management

Implemented new command and query handlers for managing chat participants. Users can now add users to chats, remove users from chats, update user permissions (roles and rights), and retrieve information about specific or all users in a chat. These changes introduce the application-layer logic for these specific chat interactions.

backend/src/MessagingPlatform.Application/CQRS/UserChats · medium confidence

Added JWT token generation and validation infrastructure

Introduced new \JwtOptions\ configuration and \JwtProvider\ implementation to handle JWT token generation and claim extraction. The provider supports creating tokens with configurable expiration and extracting user identifiers (SID and name) from validated tokens.

backend/src/MessagingPlatform.Infrastructure/Security · high confidence

Added chat deletion capability for chat owners

Users can now delete their own chats. The new DeleteChatCommand and its handler enforce that only the chat owner can perform the deletion, returning a clear error if the user lacks ownership or the chat does not exist.

backend/src/MessagingPlatform.Application/CQRS/Chats/Commands/DeleteChat · high confidence

Added new enums for chat permissions, roles, and types

Introduced three new domain enums to structure chat-related data: ChatRights (a flags-based enum for Read, Write, Update, and Delete permissions), ChatRole (defining Viewer, Member, Admin, and Owner), and ChatType (specifying Private, Group, and Channel). These additions provide a structured way to manage chat access control, user roles, and chat categories within the messaging platform.

backend/src/MessagingPlatform.Domain/Enums · high confidence

Implement CQRS handlers for message creation, deletion, and updates

The backend's messaging platform now includes CQRS command and query handlers for managing messages. Users can create new messages, delete existing ones, and update message content. The update operation enforces user permissions, returning a failure if the user lacks rights to modify the message. Additionally, a query handler allows retrieving all messages for a given chat.

backend/src/MessagingPlatform.Application/CQRS/Messages · high confidence

Implemented core account, chat, and user management services

Added new service implementations for account management (sign-up/sign-in with JWT tokens), chat creation (private, group, and channel types), user profile handling, password hashing, and cookie management within the messaging platform's infrastructure layer.

backend/src/MessagingPlatform.Infrastructure/Services · high confidence

Initial database schema for messaging platform

Added the initial Entity Framework Core migration for the messaging platform, establishing the database schema for core entities including Chats, Messages, Users, and the UserChat join table. This migration defines the foundational data structures required for the application's persistence layer.

backend/src/MessagingPlatform.Infrastructure/Persistence/Migrations · high confidence

Initial project structure and deployment configuration

The repository is initialized with a complete project structure for a 'Messaging Platform' application, including a .NET backend (using ASP.NET Core, Entity Framework Core, MediatR, and SignalR) and an Angular/TypeScript frontend. This entry adds the foundational configuration files: a Dockerfile for the backend, a docker-compose.yml to orchestrate the backend, frontend, and PostgreSQL database, and a .dockerignore file. The solution file (MessagingPlatform.sln) is updated to include the new backend and test projects, and global.json is removed.

(repo-wide) · high confidence

Initial web application scaffolding and UI components

The web application has been initialized with a complete set of Angular components and configuration files. This includes the core app shell, routing, and the account management features (sign-in, sign-up, and profile views). Additionally, the main layout for the chat interface has been added, featuring a sidebar for chat selection and a chat component for displaying and sending messages. The project also includes standard configuration files (Dockerfile, .gitignore, .editorconfig) and static assets (SVG icons).

web · high confidence

Introduce chat-specific data transfer objects

Added GetUserChatDto and UpdateUserPermissionsDto to the UserChatDTOs namespace. GetUserChatDto exposes user and chat metadata (UserId, GetUser, ChatId, JoinedAt), while UpdateUserPermissionsDto allows updating ChatRights and ChatRole for a user within a chat.

backend/src/MessagingPlatform.Application/Common/Models/UserChatDTOs · high confidence

Introduces CQRS command handlers for user management

Adds new CQRS command handlers for user operations, including AddUser, DeleteUser, SignIn, and UpdateUser. Each handler implements the ICommandHandler interface and delegates to specific services (IAccountService, IUserRepository, IUserService) to perform the underlying logic. The handlers return standardized Result types, with SignIn and AddUser wrapping authentication token generation, while UpdateUser modifies user profile data.

backend/src/MessagingPlatform.Application/CQRS/Users/Commands · high confidence

Introduces domain entities for chat, messages, and users

The backend now includes new domain models for Chat, Message, and User, establishing the core messaging functionality. Users can create chats, send and receive messages, and manage chat participants with specific roles and rights. The implementation enforces business rules such as preventing removal of users from private chats and ensuring users have the necessary permissions to perform actions like sending messages.

backend/src/MessagingPlatform.Domain/Entities · high confidence

Introduces repository implementations for chat, message, and user data access

The backend now includes concrete repository classes (ChatRepository, MessageRepository, UserRepository, and a generic Repository base) that implement the domain interfaces for data access. This change provides the underlying data access layer for the messaging platform, enabling the application to interact with the database for chat, message, and user entities.

backend/src/MessagingPlatform.Infrastructure/Repositories · high confidence

Messaging Platform API initialization and configuration

The backend API entry point (Program.cs) has been established, configuring the application to listen on port 9000 and enabling Swagger for development. The configuration includes CORS settings allowing requests from localhost:4200, SignalR support for real-time communication, and automatic database migration on startup. Additionally, the appsettings.json file has been moved and updated to include a PostgreSQL connection string and JWT authentication options.

backend/src/MessagingPlatform.Api · high confidence

New API controllers for user, chat, and message management

The backend now exposes REST endpoints for account management, chat operations, and message handling. The AccountController provides endpoints for user sign-up, sign-in, sign-out, and profile updates, with authentication tokens stored in cookies. The ChatController enables creating, retrieving, updating, and deleting chats, while the MessageController allows adding, updating, and deleting messages within a chat. Additionally, the UserChatController provides endpoints to manage chat participants, including adding/removing users and updating permissions. These controllers implement the CQRS pattern, delegating logic to corresponding command and query handlers.

backend/src/MessagingPlatform.Api/Controllers · high confidence

New domain interfaces for chat, message, and user repositories

The backend's domain layer now exposes explicit repository interfaces for core entities: IChatRepository, IMessageRepository, IUserRepository, and a generic IRepository, alongside IJwtProvider. These interfaces define the data access contracts for creating, retrieving, updating, and deleting chats, messages, and users, as well as JWT token generation and claim extraction, enabling the application to interact with the underlying data store through these abstractions.

backend/src/MessagingPlatform.Domain/Interfaces · medium confidence

Support for creating private, group, and channel chats

Users can now create different types of chats—private, group, or channel—by specifying the chat type and providing the usernames of the participants. The system resolves usernames to user IDs and delegates the creation logic to the appropriate service method, ensuring that private chats require at least one valid participant.

backend/src/MessagingPlatform.Application/CQRS/Chats/Commands/CreateChat · medium confidence

Architecture

Centralized dependency injection setup for the application layer

The application layer now includes a centralized \DependencyInjection\ class that registers all command/query handlers and validators from the assembly. This change simplifies service registration by automatically scanning for handler types and binding them as scoped services, ensuring consistent dependency injection across the application.

backend/src/MessagingPlatform.Application · high confidence

Behavioural changes

The backend's dependency injection configuration has been consolidated into a new \DependencyInjection.cs\ file within the \MessagingPlatform.Infrastructure\ project. This change registers all infrastructure services, including database contexts, repositories, and application services. Crucially, it configures ASP.NET Core authentication to validate JWT Bearer tokens while also supporting cookie-based authentication by reading the 'token' from cookies, allowing the application to accept authentication tokens from either header or cookie sources.

backend/src/MessagingPlatform.Infrastructure · high confidence

Explicit database mapping for messaging entities

The persistence layer now uses explicit configuration classes to define the database schema for Chat, Message, User, and UserChat entities. This change introduces specific constraints, such as title length limits, unique username indexes, and cascade delete behaviors for relationships, ensuring the database structure aligns with the domain model.

backend/src/MessagingPlatform.Infrastructure/Persistence/Configurations · high confidence

Introduce AppDbContext with entity sets and configuration mappings

The persistence layer now includes an AppDbContext class that defines DbSets for User, Message, Chat, and UserChat entities. The context is configured to apply mapping configurations for each entity type, establishing the database schema for the messaging platform.

backend/src/MessagingPlatform.Infrastructure/Persistence · high confidence

Introduce new user data transfer objects

The backend now exposes dedicated data transfer objects for retrieving and updating user information. The new \GetUserDto\ includes fields for first name, last name, username, email, bio, online status, and account creation date. The \UpdateUserDto\ allows modification of first name, last name, email, and bio, while explicitly excluding username and password fields from updates.

backend/src/MessagingPlatform.Application/Common/Models/UserDTOs · high confidence

Introduced message data transfer objects for CRUD operations

Added new DTOs to the backend application to support message management: CreateMessageDto for creating messages with chat and content, DeleteMessageDto for identifying messages by sender and ID, UpdateMessageDto for modifying message content, and GetMessageDto for retrieving message details including sender, content, timestamps, and read status.

backend/src/MessagingPlatform.Application/Common/Models/MessageDTOs · high confidence

Introduces CQRS abstractions and domain service interfaces

The application layer now includes new abstractions for the Command and Query patterns (ICommand, ICommandHandler, IQuery, IQueryHandler) along with a generic Result type (IResult, Error, Result) to standardize command/query handling and error reporting. Additionally, new infrastructure interfaces (IAccountService, IChatService, ICookieService, IPasswordHasher, IUserService) define the contract for account management, chat operations, cookie handling, password hashing, and user data access.

backend/src/MessagingPlatform.Application/Abstractions, backend/src/MessagingPlatform.Application/Common, backend/src/MessagingPlatform.Infrastructure/Interfaces · high confidence

New chat data transfer objects introduced

The backend now exposes four new Data Transfer Objects (DTOs) for chat operations: CreateChatDto, GetChatDto, GetChatSidebarDto, and UpdateChatDto. These models define the structure for creating chats (with title, type, and list of usernames), retrieving full chat details (including messages and user chats), fetching sidebar summaries (last message info and unread counts), and updating chat titles.

backend/src/MessagingPlatform.Application/Common/Models/ChatDTOs · high confidence

Refactor chat retrieval to filter by user

The GetChats query now requires a UserId parameter, ensuring that only chats belonging to the authenticated user are returned. The handler implementation was updated to pass this UserId to the chat repository, and the response is mapped to a new GetChatSidebarDto containing chat metadata such as the last message content, sender, timestamp, and unread message count.

backend/src/MessagingPlatform.Application/CQRS/Chats/Queries/GetChats · high confidence

Refactored chat update logic to enforce role-based permissions

The chat update command has been refactored to explicitly check user permissions before allowing title changes. The handler now verifies that the requesting user is an Admin or Owner of the chat, returning a failure if the user lacks the necessary role. Additionally, the implementation now catches DomainException during the rename operation to handle invalid title updates gracefully.

backend/src/MessagingPlatform.Application/CQRS/Chats/Commands/UpdateChat · high confidence

Removed default Weather Forecast API and configuration

The default Weather Forecast endpoint and its associated configuration have been removed from the MessagingPlatform.Api project. This includes the deletion of the HTTP request file, the Program.cs entry point that registered Swagger/OpenAPI and the /weatherforecast route, and the appsettings.json file containing logging and host settings.

MessagingPlatform.Api · high confidence

Test coverage

Added integration and domain tests for chat and message functionality

Added new test files in the backend/tests directory to cover the messaging platform's core features. This includes integration tests for creating, updating, and deleting chats and messages, as well as domain unit tests for Chat, Message, and User entities. The changes also introduce a PostgreSQL test container fixture and a shared integration test base class to support these new tests.

backend/tests · high confidence

Dependencies

Upgrade to .NET 10.0 and Angular 18.2

The backend projects have been upgraded to target .NET 10.0, with corresponding updates to Microsoft.AspNetCore.\* and Microsoft.EntityFrameworkCore packages to version 10.0.1. The frontend web application has been upgraded to Angular 18.2, including the CLI and build tools. These changes update the development environment and runtime dependencies for both the server and client sides of the application.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 42 → 39 (-3.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 73 → 73 (+0.1)
  • Architecture 74 → 74 (+0.0)
  • Maturity 63 → 63 (-0.0)
  • Readiness 31 → 26 (-4.3)
  • Security 39 → 40 (+0.6)
  • Domain Modelling 96 (new)
  • Accessibility 61 → 46 (-14.9)

Resolved (87)

  • Bounded contexts not declared
  • Change coupling: app.component.ts ↔ app.routes.ts (web/src/app/app.component.ts)
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Duplicated block (8 lines × 2) (backend/src/MessagingPlatform.Infrastructure/Services/ChatService.cs)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • …and 67 more

New (113)

  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Critical CVE: [GHSA redacted] (web/package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (15 lines × 2) (backend/src/MessagingPlatform.Application/CQRS/UserChats/Commands/RemoveUserFromChat/RemoveUserFromChatCommandHandler.cs)
  • Duplicated block (9 lines × 2) (backend/src/MessagingPlatform.Infrastructure/Services/ChatService.cs)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • High CVE: [GHSA redacted] (web/package-lock.json)
  • …and 93 more

API surface

  • Unchanged — 24 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sentemon/MessagingPlatform was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e57d685733bf8622d8128a290ed473cd20b827ef — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.